VDB

CVE-2025-4920

CVE-2025-4920 PUBLISHED

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4 and Firefox ESR < 128.10.1.

EPSS 0.02% · 2.5th percentile

Risk Scores

EPSS Score
0.02%
2.5th percentile

Timeline

  • May 17, 2025 PoC Published
  • May 18, 2025 EPSS Score
  • May 18, 2025 PoC Published
  • May 18, 2025 PoC Published
  • May 18, 2025 CVE Rejected
  • May 18, 2025 CVE Updated
  • Apr 2, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›